Privacy notice — review draft

This working notice documents the intended privacy position for Boundry. It remains subject to operational verification and Australian legal review.

Last updated 21 August 2026

Not approved for production clickwrapThis is working legal copy, not a counsel-approved final policy. The operator details, data inventory, request process, overseas-processing disclosures, and contact channel must be verified before release.

1. Scope

This policy applies to boundry.dev, Boundry accounts, the Boundry dashboard, support interactions, and the Boundry Email service. It explains our own handling of personal information and our handling of customer data on a customer's instructions.

Customers decide what they send through Boundry Email and are responsible for their relationship with recipients. Their own privacy notices and legal obligations continue to apply.

2. Information we handle

Information Boundry handles, with examples and purposes
InformationExamplesWhy we handle it
Account and organisation informationName, work email, login, organisation membershipAuthentication, account administration, and support
Project and configuration informationProject name, selected region, domains, API-key metadataOperate and secure the service
Communication contentRecipients, subject, message body, attachments, inbound mailProcess email on the customer’s instructions
Delivery and operational informationMessage IDs, timestamps, delivery events, logs, webhook attemptsDeliver, troubleshoot, secure, and evidence the service
Support and correspondenceQuestions, incident reports, and material sent to supportRespond to requests and improve the service
Website and device informationIP address, browser, request metadata, and essential cookiesDeliver, authenticate, protect, and diagnose the website

3. How we collect information

We collect personal information:

  • directly from you when you create an account or contact us;
  • from your organisation when it adds you to a Boundry account;
  • through customer use of the API, dashboard, and inbound service;
  • from delivery and infrastructure providers when they return events needed to operate the service; and
  • automatically when our website and security providers handle a request.

4. How we use information

We use personal information to:

  • provide, authenticate, and administer Boundry;
  • process communications according to customer instructions;
  • secure accounts, prevent abuse, and investigate incidents;
  • support customers and diagnose service problems;
  • manage billing and contractual relationships when applicable;
  • meet legal obligations and enforce our Terms; and
  • improve the service using operational information that is limited to what we need for that purpose.

5. Who receives information

We disclose information to service providers that help us operate Boundry, as listed in our subprocessor register. Access is limited to the purpose for which the provider is engaged.

An email must also be handed to the recipient's mailbox provider and the networks needed to reach it. Those parties are selected by the recipient or are inherent in email delivery. They are outside the Boundry regional communication boundary after handoff.

We may disclose information when required by law, to protect the rights or safety of customers and others, in connection with a corporate transaction, or with your consent.

6. Location and overseas processing

Sydney is Boundry Email's first communication region. The regional API, message database, queues, delivery integration, event handling, and designated object storage are built for AWS ap-southeast-2 and the corresponding Sydney deployment.

Not every category of information is communication content. Identity and organisation data is handled by Clerk. Cloudflare operates the website and network edge. Clerk may process account information in the United States and other countries where it or its providers operate. Cloudflare processes requests through a global network. Recipient infrastructure may be located in any country selected by a recipient or their organisation. The exact boundary and known exceptions are set out in the Sydney Region Manifest.

7. Cookies

Boundry uses authentication and session technology to operate account access. A complete production cookie, telemetry, and website-tracking inventory still needs to be verified before this notice is final.

8. Retention and deletion

We keep personal information for as long as it is reasonably needed to provide and secure the service, meet contractual and legal obligations, resolve disputes, and maintain appropriate business records. We then delete or de-identify it where practicable.

Communication content and delivery records have different operational lifecycles. Customer-configurable retention is not implemented or enforced. Backup retention, restoration, and deletion behaviour are not yet operationally verified.

9. Security and data incidents

We use technical and organisational safeguards designed for the sensitivity of the information we handle. Verified product boundaries include permanent project regions, project- and region-scoped credentials, and short-lived dashboard sessions that call the regional API directly. See our Security page for current controls and gaps.

If a data incident occurs, we will investigate it and make required notifications under applicable law, including Australia's Notifiable Data Breaches scheme where it applies.

10. Access, correction, and complaints

You may ask to access or correct personal information we hold about you. You may also make a privacy complaint. Contact us with enough detail to identify the relevant account or interaction. We may need to verify your identity before acting and may direct recipient requests to the customer that controlled the communication.

If you are not satisfied with a response, you may be entitled to contact the Office of the Australian Information Commissioner.

11. Contact

Privacy Officer
Flindev Pty Ltd
NSW 2260, Australia
privacy@boundry.dev

12. Changes to this policy

We may update this policy when the service, our providers, or legal requirements change. We will publish the new effective date here and provide additional notice when a change materially affects how we handle personal information.

Questions about the boundary?

The Sydney Region Manifest follows communication data end to end. Support can answer whatever it leaves open.